Ransomcrow Ransomware 🔐 (. Encrypted File) — Removal Guide
Ransomcrow Virus: What Is Known So Far? Ransomcrow Will Add Its Specific. Encrypted Extension to Every File’s Name. for Example, a File Entitled “Photo. Jpg”...
Ransomcrow virus: what is known so far?
Ransomcrow will add its specific .encrypted extension to every file’s name. For example, a file entitled “photo.jpg” will be turned into “photo.jpg.encrypted”. Likewise, the Excel sheet named “table.xlsx” will be altered to “table.xlsx.encrypted”, and so forth.
In each folder that contains the encoded files, a readme.txt file will appear. It is a ransom money memo. Therein you can find information about the ways of contacting the racketeers and some other information. The ransom note usually contains a description of how to purchase the decryption tool from the racketeers. That is how they do it.
| Name | Ransomcrow Virus |
| Extension | .encrypted |
| Ransomware note | readme.txt |
| Ransom | €50 |
| Detection1 | TrojanDownloader:Win32/Waledac.C, Win32:SMSSend-ADN [Trj], Ransom:Win32/StopCrypt.PCG!MTB |
| Symptoms | Your files (photos, videos, documents) have a .encrypted extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Ransomcrow virus |
The readme.txt file accompanying the Ransomcrow ransomware provides the following frustrating information:
All of your files have been encrypted Your computer was infected with a ransomware virus. Your files have been encrypted and you won\'t be able to decrypt them without our help. What can I do to get my files back? You can buy the decrypter, it will leave your pc as it was before the encryption. The price is 50€ You can buy cryptos here Coinmama - hxxps:// Bitpanda - hxxps:// Payment informationAmount: 0.1473766 BTC Bitcoin Address: 1Cee1QKq46myiLVL1v1y5gq751piPGGHNs
In the picture below, you can see what a folder with files encrypted by the Ransomcrow looks like. Each filename has the “.encrypted” extension added to it.
How did my machine catch Ransomcrow ransomware?
Nowadays, there are three most popular ways for hackers to have the Ransomcrow virus working in your digital environment. These are email spam, Trojan infiltration and peer-to-peer networks.
If you access your mailbox and see emails that look like familiar notifications from utility services providers, delivery agencies like FedEx, Internet providers, and whatnot, but whose mailer is unknown to you, be wary of opening those emails. They are very likely to have a viral item attached to them. Therefore, it is even more dangerous to download any attachments that come with emails like these.
Another option for ransom hunters is a Trojan horse scheme2. A Trojan is an object that infiltrates into your PC pretending to be something legal. For example, you download an installer of some program you need or an update for some software. However, what is unpacked turns out to be a harmful agent that corrupts your data. As the update wizard can have any title and any icon, you have to make sure that you can trust the resource of the things you’re downloading. The best thing is to use the software developers’ official websites.
As for the peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is reasonable to scan the directory containing the downloaded files with the anti-malware utility as soon as the downloading is finished.